-
Feed de notícias
- EXPLORAR
-
Páginas
-
Grupos
-
Eventos
-
Reels
-
Blogs
-
Marketplace
-
Offers
-
Jobs
CISM Exam Changes November 3, 2026: A Complete Guide for Candidates
The Certified Information Security Manager (CISM) exam is changing on November 3, 2026. Candidates planning to take the exam on or after this date need to prepare against the updated Exam Content Outline rather than relying entirely on materials aligned with the previous version.
The update does not redesign CISM from the ground up. Its four core domains remain unchanged, but ISACA has adjusted domain weightings and updated content to reflect the responsibilities of modern information security managers. The revised exam places greater emphasis on information security strategy and program development while introducing enterprise architecture and information security architecture as new content areas.
Watch Cert Mage YouTube video for a complete and easy explanation.
What Is Changing in the CISM Exam on November 3, 2026?
ISACA announced that the updated CISM exam will become available on November 3, 2026. Updated preparation materials became available from September 1, giving candidates time to transition to the revised content.
The most important changes are:
-
Revised domain weightings
-
Greater focus on information security strategy
-
Increased attention to security program development
-
Addition of enterprise architecture
-
Addition of information security architecture
-
Updated preparation resources aligned with current security responsibilities
The certification remains management-focused, so candidates should continue approaching questions from the perspective of an information security manager rather than primarily as a technical implementer.
Old vs New CISM Domain Weightings
The four CISM domains remain the same. Only two percentages change.
|
CISM Domain |
Before Nov. 3, 2026 |
From Nov. 3, 2026 |
|
Information Security Governance |
17% |
18% |
|
Information Security Risk Management |
20% |
20% |
|
Information Security Program |
33% |
33% |
|
Incident Management |
30% |
29% |
The numerical changes appear small. Governance increases by one percentage point, while Incident Management decreases by one percentage point. Risk Management and Information Security Program retain their existing weighting.
However, candidates should not assume the update is insignificant. The content changes inside the domains are more important than the percentage adjustments.
Domain 1: Information Security Governance – 18%
Information Security Governance increases from 17% to 18%.
Governance remains concerned with connecting security priorities to enterprise objectives. Candidates should understand how leadership, organizational structures, governance frameworks, policies, responsibilities, and strategic planning support information security.
What Candidates Should Focus On
Important areas include:
-
Enterprise governance
-
Organizational objectives
-
Security strategy
-
Roles and responsibilities
-
Legal and regulatory considerations
-
Governance frameworks
-
Strategic planning
-
Security investment and resources
-
Architecture considerations
The updated exam's increased emphasis on information security strategy means candidates should be comfortable thinking at the organizational level.
Instead of asking only whether a control is technically effective, consider whether it supports business objectives, risk appetite, governance requirements, and long-term security strategy.
Domain 2: Information Security Risk Management – 20%
Information Security Risk Management remains at 20%.
This domain covers identifying, assessing, responding to, monitoring, and communicating information security risks.
Candidates should understand:
-
Risk identification
-
Threats and vulnerabilities
-
Risk assessment
-
Risk analysis
-
Risk treatment
-
Risk ownership
-
Control ownership
-
Risk monitoring
-
Risk reporting
-
Business impact
The unchanged percentage does not mean candidates should reduce their study time here. Risk management influences decisions across governance, security programs, architecture, and incident management.
CISM questions often require candidates to think about business risk before selecting a technical response.
Domain 3: Information Security Program – 33%
Information Security Program remains the largest domain at 33%, making it a major preparation priority.
ISACA states that the revised exam gives greater emphasis to information security strategy and program development. Candidates should therefore understand not just how security programs operate, but how they are designed to support enterprise requirements.
Important Program Topics
Focus on:
-
Security program development
-
Program resources
-
Information assets
-
Policies and procedures
-
Security frameworks
-
Control selection
-
Control implementation
-
Control evaluation
-
Security awareness
-
Third-party services
-
Program metrics
-
Management reporting
Enterprise architecture and information security architecture also deserve attention because ISACA specifically identifies these as new content areas in the updated exam.
Candidates should understand architecture from a management perspective: how business processes, technologies, information, controls, and security requirements fit together.
Domain 4: Incident Management – 29%
Incident Management decreases slightly from 30% to 29%.
The domain still represents almost one-third of the exam, so it remains a major study area.
Key topics include:
-
Incident response planning
-
Business impact analysis
-
Business continuity
-
Disaster recovery
-
Incident classification
-
Response readiness
-
Incident investigation
-
Containment
-
Eradication
-
Recovery
-
Communications
-
Post-incident reviews
The small weighting decrease should not lead candidates to deprioritize incident management significantly.
Managers need to understand how organizations prepare for incidents, coordinate responses, communicate with stakeholders, recover operations, and learn from security events.
Why Enterprise Architecture Matters in the New CISM Exam
One of the most notable CISM exam changes is the explicit addition of enterprise architecture and information security architecture.
Security managers increasingly oversee environments involving cloud services, third parties, distributed systems, identity platforms, data systems, applications, and emerging technologies.
Architecture knowledge helps managers understand:
-
How business requirements influence technology
-
Where security controls should operate
-
How security architecture supports enterprise strategy
-
How architectural decisions affect risk
-
How security requirements integrate across systems
-
How technology dependencies affect security programs
Candidates do not need to approach these subjects as enterprise architects. CISM remains focused on security management. The objective is understanding architecture sufficiently to make appropriate governance, risk, and program decisions.
How Candidates Should Change Their Study Plan
Candidates taking CISM on or after November 3 should deliberately transition to updated material.
-
Download the updated Exam Content Outline. Use it as your primary study checklist.
-
Replace outdated preparation resources. Confirm that books, courses, and question sets reflect the November 2026 changes.
-
Review architecture topics. Add enterprise architecture and information security architecture to your study schedule.
-
Strengthen strategy knowledge. Practice connecting information security decisions with business objectives and enterprise strategy.
-
Prioritize Domain 3. Information Security Program remains the largest domain at 33%.
-
Practice management-level scenarios. Evaluate questions from the perspective of governance, risk, business impact, and management responsibility.
-
Track weaknesses by domain. Use practice questions to identify where additional review is necessary.
Candidates looking for additional question-based preparation can review the CISM exam resources available through Cert Mage while ensuring their preparation remains aligned with ISACA's November 2026 Exam Content Outline.
Old CISM Materials vs Updated Materials
Candidates should be careful when using resources produced for the previous blueprint.
ISACA specifically recommends that anyone taking the exam on or after November 3, 2026 use updated preparation materials covering the changes.
Older materials may still explain many useful CISM concepts because the four domains remain intact. However, they should not be your only resource.
Updated materials are particularly important for:
-
Revised objectives
-
Enterprise architecture
-
Information security architecture
-
Strategy-related content
-
Program-development emphasis
-
New domain alignment
-
Updated practice scenarios
Use the exam date, not the date you begin studying, to determine which outline should guide preparation.
Practical Tips for the Updated CISM Exam
CISM tests management judgment as much as terminology.
During preparation:
-
Think from a security manager's perspective.
-
Connect security decisions to business objectives.
-
Understand risk before selecting controls.
-
Distinguish governance from implementation.
-
Learn stakeholder responsibilities.
-
Review architecture at a management level.
-
Practice prioritization questions.
-
Analyze why incorrect answers are weaker.
-
Use updated questions and study materials.
-
Allocate study time according to domain weightings.
Avoid memorizing isolated answers. Scenario wording may change while testing the same management principle.
What Is Not Changing?
The update preserves the overall CISM structure.
The exam still consists of 150 questions covering four job-practice domains.
Those domains remain:
-
Information Security Governance
-
Information Security Risk Management
-
Information Security Program
-
Incident Management
This means candidates who already prepared using the previous outline do not need to restart completely. They should identify the differences, update their materials, and strengthen newly emphasized areas.
Conclusion
The November 3, 2026 CISM exam update is an evolution rather than a complete redesign. Governance moves from 17% to 18%, Incident Management shifts from 30% to 29%, and the other two domain percentages remain unchanged. More importantly, the revised content increases attention on security strategy, program development, enterprise architecture, and information security architecture.
Candidates testing from November 3 onward should use updated preparation resources and adjust their study plans accordingly. Focus on management-level decision-making, business alignment, risk, architecture, program effectiveness, and incident readiness rather than relying primarily on technical memorization.
FAQs
When does the new CISM exam start?
The updated CISM exam becomes available on November 3, 2026. ISACA recommends candidates testing on or after that date use updated preparation materials.
Are the CISM domains changing?
No. The same four domains remain: Information Security Governance, Information Security Risk Management, Information Security Program, and Incident Management. Their content and selected weightings are being updated.
What are the new CISM domain percentages?
The updated weightings are Governance 18%, Risk Management 20%, Information Security Program 33%, and Incident Management 29%.
Can I use old CISM study materials after November 3?
Older resources can still help with concepts that remain relevant, but ISACA strongly recommends updated preparation materials for exams taken on or after November 3, 2026.
What new topics should I study?
Candidates should pay particular attention to enterprise architecture, information security architecture, information security strategy, and program development because ISACA specifically highlights these areas in the update.
Read More: How PMP Practice Questions Help Identify Your Weak Areas
- Art
- Causes
- Crafts
- Dance
- Drinks
- Film
- Fitness
- Food
- Jogos
- Gardening
- Health
- Início
- Literature
- Music
- Networking
- Outro
- Party
- Religion
- Shopping
- Sports
- Theater
- Wellness